信息安全研究 ›› 2018, Vol. 4 ›› Issue (10): 904-913.

• 风险评估专题 • 上一篇    下一篇

电力行业工业控制系统信息安全风险评估研究

魏晓雷1,刘龙涛2   

  1. 1. 中航国际金网
    2. 国家信息中心信息与网络安全部
  • 收稿日期:2018-10-11 出版日期:2018-10-15 发布日期:2018-10-11
  • 通讯作者: 魏晓雷
  • 作者简介:魏晓雷 本科,工程师,主要研究方向为网络安全、数据安全及工控安全 刘龙涛 硕士,工程师,主要研究方向为Web应用安全、工控安全、云计算安全

Research on Information Security Risk Assessment of Power Industry Control System

  • Received:2018-10-11 Online:2018-10-15 Published:2018-10-11

摘要: 摘要简要地分析了电力行业工业控制系统面临的信息安全威胁,列出了电力行业工业控制系统主要的安全问题,并在此基础上建立了工业控制系统信息安全风险评估与管理模型,提出了工业控制系统信息安全风险评估的方法和流程,总结出了一套针对工业控制系统的信息安全风险评估解决方案,并阐述了关于风险评估和工业控制系统网络安全工作的一些新认识,进一步分析了工业控制系统网络安全脆弱性,借此提请有关单位和有关主管部门应进一步明确和规范工业控制系统信息安全风险评估工作的管理,加强有关评估标准、技术的研究,增加面向专业测评机构和用户单位的技术培训,推动我国工业控制系统信息风险评估工作的发展.

关键词: 电力行业, 工业控制系统, 信息安全, 风险评估, 脆弱性

Abstract: This paper briefly analyzed the information security threats faced by the industrial control system in the power industry. The main safety problems of industrial control system in electric power industry are listed. We also built an information security risk assessment and management model for industrial control systems, proposed methods and processes for information security risk assessment of industrial control systems. Hence, we summed up a set of information security risk assessment solutions for industrial control systems. Some new understandings about risk assessment and industrial control system network security are also discussed. The vulnerability of industrial control system network security is further analyzed. Therefore, the relevant units and relevant competent departments should further clarify and standardize the management of information security risk assessment of industrial control systems. Strengthen research on evaluation standards and technology. Increasing technical training for professional evaluation organizations and user units. Promoting the development of information risk assessment for industrial control systems in China.

Key words: power industry, industrial control system, information security, risk assessment, vulnerability